{"_id":"@am25/gate-next","_rev":"13-509b1819b5579fb3dbfcd822a767550f","name":"@am25/gate-next","dist-tags":{"latest":"4.0.0"},"versions":{"1.0.1":{"name":"@am25/gate-next","version":"1.0.1","keywords":["oauth2","oidc","openid-connect","authentication","nextjs","sso","identity-provider","am25","gate"],"author":{"url":"https://alemartir.com","name":"Alejandro Mártir"},"license":"MIT","_id":"@am25/gate-next@1.0.1","maintainers":[{"name":"itsmrtr","email":"hola@alemartir.com"}],"homepage":"https://github.com/am25-labs/am-gate-next#readme","bugs":{"url":"https://github.com/am25-labs/am-gate-next/issues"},"dist":{"shasum":"8c839a25bd5b8810491cc8ded337d359f4ea4ff5","tarball":"https://registry.npmjs.org/@am25/gate-next/-/gate-next-1.0.1.tgz","fileCount":10,"integrity":"sha512-ZF7nh0Tl1Mwah31FBqnLcpDgALe4Xs+qoW1HrdqwxYT/iHhR6I87TFgjJm9jNCvr4pckdDM3IR2tPoUTGDdjXw==","signatures":[{"sig":"MEYCIQDZbhott9il7jCrGPXj+Zs5xqOiUW9GLouyRHFusyxm7QIhAN2jIAlAiiJM2cwxGDpT10AbwmRchPzr8OveI8tOi5BB","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":36499},"main":"./src/index.js","type":"module","engines":{"node":">=18"},"exports":{".":{"import":"./src/index.js","default":"./src/index.js"}},"gitHead":"a987f56c8f74ba8f573ee76d74f0bfd71a4331f0","_npmUser":{"name":"itsmrtr","email":"hola@alemartir.com"},"repository":{"url":"git+https://github.com/am25-labs/am-gate-next.git","type":"git"},"_npmVersion":"10.9.2","description":"AM25 Gate (OAuth2+OIDC Authentication) SDK for Next.js","directories":{},"_nodeVersion":"22.14.0","dependencies":{"jose":"^5.0.0"},"_hasShrinkwrap":false,"peerDependencies":{"next":">=16.0.0","react":">=19.0.0"},"_npmOperationalInternal":{"tmp":"tmp/gate-next_1.0.1_1773375946032_0.18043861525902605","host":"s3://npm-registry-packages-npm-production"}},"1.0.2":{"name":"@am25/gate-next","version":"1.0.2","keywords":["oauth2","oidc","openid-connect","authentication","nextjs","sso","identity-provider","am25","gate"],"author":{"url":"https://alemartir.com","name":"Alejandro Mártir"},"license":"MIT","_id":"@am25/gate-next@1.0.2","maintainers":[{"name":"itsmrtr","email":"hola@alemartir.com"}],"homepage":"https://github.com/am25-labs/am-gate-next#readme","bugs":{"url":"https://github.com/am25-labs/am-gate-next/issues"},"dist":{"shasum":"3ec9ad02bdde4778fa532180dd8965d084da2a57","tarball":"https://registry.npmjs.org/@am25/gate-next/-/gate-next-1.0.2.tgz","fileCount":10,"integrity":"sha512-xFdDosfD1o7uyBJu6J74uOrsYybhqvtg84ksJipXeo0GYU34yH3ERU4vDv8URil2AnNALpNfjSUytovRPkqW5Q==","signatures":[{"sig":"MEUCIDrTuWQjuBrYQ2Ik4OCGKMyQtpID5qHpoc8R5EM4uNXQAiEApa9qUXilv1bJaDDs41v0HR6m1OEyFllWTfGSz19IzVM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":36938},"main":"./src/index.js","type":"module","engines":{"node":">=18"},"exports":{".":{"import":"./src/index.js","default":"./src/index.js"}},"gitHead":"4929b2669da125a31dc70093c252dac5a1977861","_npmUser":{"name":"itsmrtr","email":"hola@alemartir.com"},"repository":{"url":"git+https://github.com/am25-labs/am-gate-next.git","type":"git"},"_npmVersion":"10.9.2","description":"AM25 Gate (OAuth2+OIDC Authentication) SDK for Next.js","directories":{},"_nodeVersion":"22.14.0","dependencies":{"jose":"^5.0.0"},"_hasShrinkwrap":false,"peerDependencies":{"next":">=16.0.0","react":">=19.0.0"},"_npmOperationalInternal":{"tmp":"tmp/gate-next_1.0.2_1773687832912_0.611949574387183","host":"s3://npm-registry-packages-npm-production"}},"1.1.0":{"name":"@am25/gate-next","version":"1.1.0","keywords":["oauth2","oidc","openid-connect","authentication","nextjs","sso","identity-provider","am25","gate"],"author":{"url":"https://alemartir.com","name":"Alejandro Mártir"},"license":"MIT","_id":"@am25/gate-next@1.1.0","maintainers":[{"name":"itsmrtr","email":"hola@alemartir.com"}],"homepage":"https://github.com/am25-labs/am-gate-next#readme","bugs":{"url":"https://github.com/am25-labs/am-gate-next/issues"},"dist":{"shasum":"aa1249dccf3b571a898136c70483da99f1364b20","tarball":"https://registry.npmjs.org/@am25/gate-next/-/gate-next-1.1.0.tgz","fileCount":17,"integrity":"sha512-rjpQd8wUvAHozH+S6CfxCcA7zoMAjLYr1w5fSIOuoxKQS0xhpBY4vzkdmpTXK/T+dgg7X3poH9fy2l3sNGgOqw==","signatures":[{"sig":"MEYCIQDTgxcbjGzCOkNKlOcvF8bYzSJU5xhRW2GpkN6lw8QVlwIhAJL5VPuNBJBxDS3Oof5s+X2W2dMKmX8L2za07aO4fsOi","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":36932},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"bce60edcc2ae0ccaafd7d6581979c0eef5905a65","scripts":{"build":"tsc","prepublishOnly":"pnpm build"},"_npmUser":{"name":"itsmrtr","email":"hola@alemartir.com"},"repository":{"url":"git+https://github.com/am25-labs/am-gate-next.git","type":"git"},"_npmVersion":"10.9.2","description":"AM25 Gate (OAuth2+OIDC Authentication) SDK for Next.js","directories":{},"_nodeVersion":"22.14.0","dependencies":{"jose":"^5.0.0"},"_hasShrinkwrap":false,"devDependencies":{"next":"16.1.7","typescript":"5.9.3","@types/node":"25.5.0","@types/react":"19.2.14"},"peerDependencies":{"next":">=16.0.0","react":">=19.0.0"},"_npmOperationalInternal":{"tmp":"tmp/gate-next_1.1.0_1773850851459_0.5329033326480803","host":"s3://npm-registry-packages-npm-production"}},"1.1.1":{"name":"@am25/gate-next","version":"1.1.1","keywords":["oauth2","oidc","openid-connect","authentication","nextjs","sso","identity-provider","am25","gate"],"author":{"url":"https://alemartir.com","name":"Alejandro Mártir"},"license":"MIT","_id":"@am25/gate-next@1.1.1","maintainers":[{"name":"itsmrtr","email":"hola@alemartir.com"}],"homepage":"https://github.com/am25-labs/am-gate-next#readme","bugs":{"url":"https://github.com/am25-labs/am-gate-next/issues"},"dist":{"shasum":"e042731837bf90aa6052a24882295bdb0a5c602e","tarball":"https://registry.npmjs.org/@am25/gate-next/-/gate-next-1.1.1.tgz","fileCount":17,"integrity":"sha512-0XB8MwNNbhYS6k+qYdR+kYfm1LZfwYkZQEgDCGDx2xT/qkFZP4eDPA9Z3R1OmI5LF4AJT8wtFW+bjDLr+TDe6g==","signatures":[{"sig":"MEUCIQCL4GiPg1kjJ8ksAHGLMPtHDtp4bl+6dW1ZK2hOTeiraQIgfymFHxx34Z0XOnj+AJbmXsDYWKNBAKr3OiTh7PIqDtI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":40103},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"0fb5b714d0c84a1f47025dd74172ba4c2ec85891","scripts":{"build":"tsc","prepublishOnly":"pnpm build"},"_npmUser":{"name":"itsmrtr","email":"hola@alemartir.com"},"repository":{"url":"git+https://github.com/am25-labs/am-gate-next.git","type":"git"},"_npmVersion":"10.9.2","description":"AM25 Gate (OAuth2+OIDC Authentication) SDK for Next.js","directories":{},"_nodeVersion":"22.14.0","dependencies":{"jose":"^5.0.0"},"_hasShrinkwrap":false,"devDependencies":{"next":"16.1.7","typescript":"5.9.3","@types/node":"25.5.0","@types/react":"19.2.14"},"peerDependencies":{"next":">=16.0.0","react":">=19.0.0"},"_npmOperationalInternal":{"tmp":"tmp/gate-next_1.1.1_1773851774371_0.26621761328493143","host":"s3://npm-registry-packages-npm-production"}},"1.2.0":{"name":"@am25/gate-next","version":"1.2.0","keywords":["oauth2","oidc","openid-connect","authentication","nextjs","sso","identity-provider","am25","gate"],"author":{"url":"https://alemartir.com","name":"Alejandro Mártir"},"license":"MIT","_id":"@am25/gate-next@1.2.0","maintainers":[{"name":"itsmrtr","email":"hola@alemartir.com"}],"homepage":"https://github.com/am25-labs/am-gate-next#readme","bugs":{"url":"https://github.com/am25-labs/am-gate-next/issues"},"dist":{"shasum":"09f91d71c2c9fc251287018de1fc9d5a3c485a0f","tarball":"https://registry.npmjs.org/@am25/gate-next/-/gate-next-1.2.0.tgz","fileCount":21,"integrity":"sha512-Wc4uUvj1ul8pe5RANL8Lg1uIleKzsLVJYw+6IT3to6wciuZYB9zbyBVI8YOCb6ooYqbcOAjRf8IP2NEuZoO56w==","signatures":[{"sig":"MEQCIB1Iwf0buTGu1BwgiTpLWxluPG7jk2MhwY70Z9DJHAuwAiB9sxZrcaTH7LtuR4LJf0mbR8LKFj3D/tcC3Iw4uiy6BA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":52458},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"994378ca50dc8827ea6a095f5ad11ed327e9c057","scripts":{"build":"tsc","prepublishOnly":"pnpm build"},"_npmUser":{"name":"itsmrtr","email":"hola@alemartir.com"},"repository":{"url":"git+https://github.com/am25-labs/am-gate-next.git","type":"git"},"_npmVersion":"10.9.2","description":"AM25 Gate (OAuth2+OIDC Authentication) SDK for Next.js","directories":{},"_nodeVersion":"22.14.0","dependencies":{"jose":"^5.0.0"},"_hasShrinkwrap":false,"devDependencies":{"next":"16.1.7","typescript":"5.9.3","@types/node":"25.5.0","@types/react":"19.2.14"},"peerDependencies":{"next":">=16.0.0","react":">=19.0.0"},"_npmOperationalInternal":{"tmp":"tmp/gate-next_1.2.0_1782946432309_0.46280604547183324","host":"s3://npm-registry-packages-npm-production"}},"1.3.0":{"name":"@am25/gate-next","version":"1.3.0","keywords":["oauth2","oidc","openid-connect","authentication","nextjs","sso","identity-provider","am25","gate"],"author":{"url":"https://alemartir.com","name":"Alejandro Mártir"},"license":"MIT","_id":"@am25/gate-next@1.3.0","maintainers":[{"name":"itsmrtr","email":"hola@alemartir.com"}],"homepage":"https://github.com/am25-labs/am-gate-next#readme","bugs":{"url":"https://github.com/am25-labs/am-gate-next/issues"},"dist":{"shasum":"beb347b4eb15ed07b76e9e53dcf385419a4e3f70","tarball":"https://registry.npmjs.org/@am25/gate-next/-/gate-next-1.3.0.tgz","fileCount":21,"integrity":"sha512-zQugRpcR0M+gN/s7x2BHi5AbiRgy6fFxupjert1Lu2khtTcCzuP56GJrQnEy+LbswpYGAFue/HkaItgxyMPdKg==","signatures":[{"sig":"MEYCIQC66JmawvZdOWr+yPJPCyJbs+Hr7smx0poT+KuCrJj3XgIhAIpyybW7ArsoMfL/j7dLNu59Q0ukmOJGuMY5qewvyRWy","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":53640},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"7754a541363cdb2067880cbc14c271d2d0b816a9","scripts":{"build":"tsc","prepublishOnly":"pnpm build"},"_npmUser":{"name":"itsmrtr","email":"hola@alemartir.com"},"repository":{"url":"git+https://github.com/am25-labs/am-gate-next.git","type":"git"},"_npmVersion":"10.9.2","description":"AM25 Gate (OAuth2+OIDC Authentication) SDK for Next.js","directories":{},"_nodeVersion":"22.14.0","dependencies":{"jose":"^5.0.0"},"_hasShrinkwrap":false,"devDependencies":{"next":"16.1.7","typescript":"5.9.3","@types/node":"25.5.0","@types/react":"19.2.14"},"peerDependencies":{"next":">=16.0.0","react":">=19.0.0"},"_npmOperationalInternal":{"tmp":"tmp/gate-next_1.3.0_1784749782399_0.7580213839233618","host":"s3://npm-registry-packages-npm-production"}},"2.0.0":{"name":"@am25/gate-next","version":"2.0.0","keywords":["oauth2","oidc","openid-connect","authentication","nextjs","sso","identity-provider","am25","gate"],"author":{"url":"https://alemartir.com","name":"Alejandro Mártir"},"license":"MIT","_id":"@am25/gate-next@2.0.0","maintainers":[{"name":"itsmrtr","email":"hola@alemartir.com"}],"homepage":"https://github.com/am25-labs/am-gate-next#readme","bugs":{"url":"https://github.com/am25-labs/am-gate-next/issues"},"dist":{"shasum":"672832f6356079570ecbab899bfa1ecd2cfd2ffa","tarball":"https://registry.npmjs.org/@am25/gate-next/-/gate-next-2.0.0.tgz","fileCount":23,"integrity":"sha512-w6z+2qhxfo+UYN0MKJRQ09k8TroJFo9p4xw+L1irj1k3lIfKi1BpJpmB+3oVth/s4LdmBKdy7tHhf08oGYZmxA==","signatures":[{"sig":"MEUCICmUkqnC+PJXcO6qv/HpTE+nLFsrjZt5ASvrLaKkwFbjAiEAiif/yffJ1Ic0+Ck6WRH6UVm3RCZ0Ybl8ZjDGJnkgY/8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":53668},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"f045a4b11d476796feddacb6eb45605deaa4ee9a","scripts":{"build":"tsc","prepublishOnly":"pnpm build"},"_npmUser":{"name":"itsmrtr","email":"hola@alemartir.com"},"repository":{"url":"git+https://github.com/am25-labs/am-gate-next.git","type":"git"},"_npmVersion":"10.9.2","description":"AM25 Gate (OAuth2+OIDC Authentication) SDK for Next.js","directories":{},"_nodeVersion":"22.14.0","dependencies":{"jose":"^5.0.0"},"_hasShrinkwrap":false,"devDependencies":{"next":"16.1.7","typescript":"5.9.3","@types/node":"25.5.0","@types/react":"19.2.14"},"peerDependencies":{"next":">=16.0.0","react":">=19.0.0"},"_npmOperationalInternal":{"tmp":"tmp/gate-next_2.0.0_1786485119071_0.2558704664630649","host":"s3://npm-registry-packages-npm-production"}},"2.1.0":{"name":"@am25/gate-next","version":"2.1.0","keywords":["oauth2","oidc","openid-connect","authentication","nextjs","sso","identity-provider","am25","gate"],"author":{"url":"https://alemartir.com","name":"Alejandro Mártir"},"license":"MIT","_id":"@am25/gate-next@2.1.0","maintainers":[{"name":"itsmrtr","email":"hola@alemartir.com"}],"homepage":"https://github.com/am25-labs/am-gate-next#readme","bugs":{"url":"https://github.com/am25-labs/am-gate-next/issues"},"dist":{"shasum":"070f0003e1f0600ee55a58ec7bc62d03df1763eb","tarball":"https://registry.npmjs.org/@am25/gate-next/-/gate-next-2.1.0.tgz","fileCount":23,"integrity":"sha512-4MHmQfU0NTZldU6mGHlkQ+s6/18ztylTZ+yNoQYy1RFXHIfna0JwzRAMimE2ptrRQAxnI9I0xD/Vy/1Kb1vKaQ==","signatures":[{"sig":"MEUCIQDdLqeRLuw37Bdji+SkZgqJvi6FkvV2yaXPaUoV6H8kowIgFsWk9lOxbS256DYrTlqLCJj6RaoUc3SfnX/Amj67EUE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":54593},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"0932375740e16cd4e3c769c8dfc7af0089dc8c6a","scripts":{"build":"tsc","prepublishOnly":"pnpm build"},"_npmUser":{"name":"itsmrtr","email":"hola@alemartir.com"},"repository":{"url":"git+https://github.com/am25-labs/am-gate-next.git","type":"git"},"_npmVersion":"10.9.2","description":"AM25 Gate (OAuth2+OIDC Authentication) SDK for Next.js","directories":{},"_nodeVersion":"22.14.0","dependencies":{"jose":"^5.0.0"},"_hasShrinkwrap":false,"devDependencies":{"next":"16.1.7","typescript":"5.9.3","@types/node":"25.5.0","@types/react":"19.2.14"},"peerDependencies":{"next":">=16.0.0","react":">=19.0.0"},"_npmOperationalInternal":{"tmp":"tmp/gate-next_2.1.0_1787817431008_0.08801176182065262","host":"s3://npm-registry-packages-npm-production"}},"3.0.0":{"name":"@am25/gate-next","version":"3.0.0","keywords":["oauth2","oidc","openid-connect","authentication","nextjs","sso","identity-provider","am25","gate"],"author":{"url":"https://alemartir.com","name":"Alejandro Mártir"},"license":"MIT","_id":"@am25/gate-next@3.0.0","maintainers":[{"name":"itsmrtr","email":"hola@alemartir.com"}],"homepage":"https://github.com/am25-labs/am-gate-next#readme","bugs":{"url":"https://github.com/am25-labs/am-gate-next/issues"},"dist":{"shasum":"98074fa5354d47e337673ffbacfec38552b11db2","tarball":"https://registry.npmjs.org/@am25/gate-next/-/gate-next-3.0.0.tgz","fileCount":25,"integrity":"sha512-vS0j7vlKzz+Uthtgltbiy3s6dhZ69PAJQTytoT584RAxYbLFyQO8HISHnCmn2aqS2lzgalnvItOo5/aQNK+VYw==","signatures":[{"sig":"MEYCIQDYRcCgPmB9020UmsoRSH05995R/KGYMRWMgzGgKqEKegIhAJg4XblN6sWx13YaqdyUVUW1skJ2K4Vp+vC9++DVzkqj","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":60010},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"3e72d585b47a147a1f10e2ea67d4a1d1411f1fd1","scripts":{"build":"tsc","prepublishOnly":"pnpm build"},"_npmUser":{"name":"itsmrtr","email":"hola@alemartir.com"},"repository":{"url":"git+https://github.com/am25-labs/am-gate-next.git","type":"git"},"_npmVersion":"10.9.2","description":"AM25 Gate (OAuth2+OIDC Authentication) SDK for Next.js","directories":{},"_nodeVersion":"22.14.0","dependencies":{"jose":"^5.0.0"},"_hasShrinkwrap":false,"devDependencies":{"next":"16.1.7","typescript":"5.9.3","@types/node":"25.5.0","@types/react":"19.2.14"},"peerDependencies":{"next":">=16.0.0","react":">=19.0.0"},"_npmOperationalInternal":{"tmp":"tmp/gate-next_3.0.0_1788294334344_0.002875203104772295","host":"s3://npm-registry-packages-npm-production"}},"4.0.0":{"name":"@am25/gate-next","version":"4.0.0","description":"AM25 Gate (OAuth2+OIDC Authentication) SDK for Next.js","type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"import":"./dist/index.js","types":"./dist/index.d.ts"}},"scripts":{"build":"tsc","prepublishOnly":"pnpm build"},"author":{"name":"Alejandro Mártir","url":"https://alemartir.com"},"homepage":"https://github.com/am25-labs/am-gate-next#readme","repository":{"type":"git","url":"git+https://github.com/am25-labs/am-gate-next.git"},"bugs":{"url":"https://github.com/am25-labs/am-gate-next/issues"},"dependencies":{"jose":"^5.0.0"},"peerDependencies":{"next":">=16.0.0","react":">=19.0.0"},"engines":{"node":">=18"},"keywords":["oauth2","oidc","openid-connect","authentication","nextjs","sso","identity-provider","am25","gate"],"license":"MIT","devDependencies":{"@types/node":"25.5.0","@types/react":"19.2.14","next":"16.1.7","typescript":"5.9.3"},"_id":"@am25/gate-next@4.0.0","gitHead":"a6b92106faf881dba19c24b161761fd02c14fa50","_nodeVersion":"22.14.0","_npmVersion":"10.9.2","dist":{"integrity":"sha512-jMCnoWv+YvSS3okZ90nUumgRf/7uxEP7YXHJkR6/lRWrr/qzxHESL/P/oGiMrdfXMCt46VBVlwL66fXF7q2oQg==","shasum":"cb16b249e05e712872e87d974732e3c0365891ec","tarball":"https://registry.npmjs.org/@am25/gate-next/-/gate-next-4.0.0.tgz","fileCount":29,"unpackedSize":67512,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIGvYbUSYAdRXot/FWU5s4b5R4hLwfBl15YOuDg7ozaM8AiBoj8g6gRMqv4wo1lwW7ZhDWyDRZDvkIkmspJ2j+y6LKA=="}]},"_npmUser":{"name":"itsmrtr","email":"hola@alemartir.com"},"directories":{},"maintainers":[{"name":"itsmrtr","email":"hola@alemartir.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/gate-next_4.0.0_1788297370992_0.13845768697438143"},"_hasShrinkwrap":false}},"time":{"created":"2026-03-13T04:25:45.804Z","modified":"2026-09-01T21:16:11.316Z","1.0.0":"2026-03-13T04:09:16.881Z","1.0.1":"2026-03-13T04:25:46.166Z","1.0.2":"2026-03-16T19:03:53.060Z","1.1.0":"2026-03-18T16:20:51.609Z","1.1.1":"2026-03-18T16:36:14.576Z","1.2.0":"2026-07-01T22:53:52.444Z","1.3.0":"2026-07-22T19:49:42.544Z","2.0.0":"2026-08-11T21:51:59.193Z","2.1.0":"2026-08-27T07:57:11.150Z","3.0.0":"2026-09-01T20:25:34.485Z","4.0.0":"2026-09-01T21:16:11.141Z"},"bugs":{"url":"https://github.com/am25-labs/am-gate-next/issues"},"author":{"name":"Alejandro Mártir","url":"https://alemartir.com"},"license":"MIT","homepage":"https://github.com/am25-labs/am-gate-next#readme","keywords":["oauth2","oidc","openid-connect","authentication","nextjs","sso","identity-provider","am25","gate"],"repository":{"type":"git","url":"git+https://github.com/am25-labs/am-gate-next.git"},"description":"AM25 Gate (OAuth2+OIDC Authentication) SDK for Next.js","maintainers":[{"name":"itsmrtr","email":"hola@alemartir.com"}],"readme":"# @am25/gate-next\n\nServer-side SDK for integrating Next.js 16+ applications with **AM25 Gate IdP**, an Identity Provider compatible with OAuth 2.0 and OpenID Connect.\n\n## Features\n\n- **TypeScript-first**: Full type definitions with exported interfaces\n- Server-first authentication: no React providers, no forced CSR\n- OAuth 2.0 + OIDC: Authorization Code flow with PKCE S256 and nonce validation\n- Login CSRF protection: short-lived host-only transaction cookies and one-time state\n- Proxy for Next.js 16: Server-level route protection\n- httpOnly Cookie: Secure session shared across subdomains\n- React Helpers: Cached functions for Server Components\n- RS256 (JWKS): Token verification using public keys, no shared secrets\n- Assigned users: Fetch the users assigned to the current client app\n- Active token validation: Signature, audience, grant revocation, and current claims\n- Federated token revocation during logout\n\n## Installation\n\n```bash\n# pnpm\npnpm add @am25/gate-next\n\n# npm\nnpm install @am25/gate-next\n\n# yarn\nyarn add @am25/gate-next\n```\n\n## Requirements\n\n- Next.js 16+\n- React 19+\n- An app registered as an OAuth client in Gate\n\n## Configuration\n\n### 1. Environment variables\n\nCreate `.env.local`:\n\n```env\n# Gate OAuth\nGATE_ISSUER=https://gate.example.com\nGATE_CLIENT_ID=your-client-id\nGATE_CLIENT_SECRET=your-client-secret\nGATE_REDIRECT_URI=https://myapp.example.com/api/auth/callback\n\n# Cookie\nCOOKIE_DOMAIN=.example.com\n\n```\n\nYou do not need `JWT_SECRET`. Tokens are verified using Gate's public key (JWKS).\n\n### 2. Create API Routes\n\n#### `/api/auth/login/route.ts`\n\nCreates the browser-bound OAuth transaction and redirects to Gate.\n\n```ts\nimport { createLoginHandler } from \"@am25/gate-next\";\nimport type { NextRequest } from \"next/server\";\n\nconst handler = createLoginHandler({\n  issuer: process.env.GATE_ISSUER!,\n  clientId: process.env.GATE_CLIENT_ID!,\n  redirectUri: process.env.GATE_REDIRECT_URI!,\n  defaultRedirect: \"/dashboard\",\n});\n\nexport async function GET(request: NextRequest) {\n  return handler(request);\n}\n```\n\n#### `/api/auth/callback/route.ts`\n\nExchanges the authorization code for tokens and sets the session cookie.\n\n```ts\nimport { createCallbackHandler } from \"@am25/gate-next\";\nimport type { NextRequest } from \"next/server\";\n\nconst handler = createCallbackHandler({\n  issuer: process.env.GATE_ISSUER!,\n  clientId: process.env.GATE_CLIENT_ID!,\n  clientSecret: process.env.GATE_CLIENT_SECRET!,\n  redirectUri: process.env.GATE_REDIRECT_URI!,\n  cookieDomain: process.env.COOKIE_DOMAIN,\n  defaultRedirect: \"/dashboard\",\n});\n\nexport async function GET(request: NextRequest) {\n  return handler(request);\n}\n```\n\n<details>\n<summary>JavaScript version</summary>\n\n```js\nimport { createCallbackHandler } from \"@am25/gate-next\";\n\nconst handler = createCallbackHandler({\n  issuer: process.env.GATE_ISSUER,\n  clientId: process.env.GATE_CLIENT_ID,\n  clientSecret: process.env.GATE_CLIENT_SECRET,\n  redirectUri: process.env.GATE_REDIRECT_URI,\n  cookieDomain: process.env.COOKIE_DOMAIN,\n  defaultRedirect: \"/dashboard\",\n});\n\nexport async function GET(request) {\n  return handler(request);\n}\n```\n\n</details>\n\n#### `/api/auth/logout/route.ts`\n\nRevokes the current OAuth grant, clears the local cookies, and logs out from Gate.\n\n```ts\nimport { createLogoutHandler } from \"@am25/gate-next\";\nimport type { NextRequest } from \"next/server\";\n\nconst handler = createLogoutHandler({\n  issuer: process.env.GATE_ISSUER!,\n  clientId: process.env.GATE_CLIENT_ID!,\n  clientSecret: process.env.GATE_CLIENT_SECRET,\n  redirectUri: process.env.GATE_REDIRECT_URI!,\n  cookieDomain: process.env.COOKIE_DOMAIN,\n  redirectTo: \"/\",\n});\n\nexport async function GET(request: NextRequest) {\n  return handler(request);\n}\n```\n\n<details>\n<summary>JavaScript version</summary>\n\n```js\nimport { createLogoutHandler } from \"@am25/gate-next\";\n\nconst handler = createLogoutHandler({\n  issuer: process.env.GATE_ISSUER,\n  clientId: process.env.GATE_CLIENT_ID,\n  clientSecret: process.env.GATE_CLIENT_SECRET,\n  redirectUri: process.env.GATE_REDIRECT_URI,\n  cookieDomain: process.env.COOKIE_DOMAIN,\n  redirectTo: \"/\",\n});\n\nexport async function GET(request) {\n  return handler(request);\n}\n```\n\n</details>\n\n### 3. Configure Proxy (Next.js 16)\n\nThe proxy protects routes by verifying the session cookie. If there is no valid session, the user is redirected to Gate to authenticate.\n\nCreate `src/proxy.ts`:\n\n```ts\nimport { createGateProxy } from \"@am25/gate-next\";\nimport type { NextRequest } from \"next/server\";\n\nconst gateProxy = createGateProxy({\n  issuer: process.env.GATE_ISSUER!,\n  clientId: process.env.GATE_CLIENT_ID!,\n  redirectUri: process.env.GATE_REDIRECT_URI!,\n  protectedPaths: [\"/dashboard\", \"/settings\"],\n  publicPaths: [\"/dashboard/public\"],\n});\n\nexport async function proxy(request: NextRequest) {\n  return gateProxy(request);\n}\n\nexport const config = {\n  matcher: [\"/dashboard/:path*\", \"/settings/:path*\"],\n};\n```\n\n<details>\n<summary>JavaScript version</summary>\n\n```js\nimport { createGateProxy } from \"@am25/gate-next\";\n\nconst gateProxy = createGateProxy({\n  issuer: process.env.GATE_ISSUER,\n  clientId: process.env.GATE_CLIENT_ID,\n  redirectUri: process.env.GATE_REDIRECT_URI,\n  protectedPaths: [\"/dashboard\", \"/settings\"],\n  publicPaths: [\"/dashboard/public\"],\n});\n\nexport async function proxy(request) {\n  return gateProxy(request);\n}\n\nexport const config = {\n  matcher: [\"/dashboard/:path*\", \"/settings/:path*\"],\n};\n```\n\n</details>\n\n### 4. Create session helpers\n\nCreate `src/lib/auth.ts`:\n\n```ts\nimport { createSessionHelpers } from \"@am25/gate-next\";\n\nexport const {\n  getSession,\n  getUser,\n  isAuthenticated,\n  requireAuth,\n  requireAdmin,\n} = createSessionHelpers({\n  issuer: process.env.GATE_ISSUER!,\n  clientId: process.env.GATE_CLIENT_ID!,\n});\n```\n\n<details>\n<summary>JavaScript version</summary>\n\n```js\nimport { createSessionHelpers } from \"@am25/gate-next\";\n\nexport const {\n  getSession,\n  getUser,\n  isAuthenticated,\n  requireAuth,\n  requireAdmin,\n} = createSessionHelpers({\n  issuer: process.env.GATE_ISSUER,\n  clientId: process.env.GATE_CLIENT_ID,\n});\n```\n\n</details>\n\n## Usage\n\n### In Server Components\n\n```tsx\nimport { requireAuth } from \"@/lib/auth\";\n\nexport default async function DashboardPage() {\n  const user = await requireAuth();\n\n  return (\n    <div>\n      <h1>Hello, {user.name}</h1>\n      <p>Email: {user.email}</p>\n      {user.isAdmin && <span>You are an administrator</span>}\n    </div>\n  );\n}\n```\n\n\n### Syncing assigned Gate users\n\nGate exposes the users assigned to the current client app through `/oauth/users`. The SDK stores an `am25_at` httpOnly access token during the OAuth callback and uses it from server-side helpers.\n\n```ts\nimport { createUserHelpers } from \"@am25/gate-next\";\nimport prisma from \"@/lib/prisma\";\n\nconst users = createUserHelpers({\n  issuer: process.env.GATE_ISSUER!,\n});\n\nexport async function syncGateUsers() {\n  return users.syncUsers(async (gateUsers) => {\n    await Promise.all(\n      gateUsers.map((user) =>\n        prisma.user.upsert({\n          where: { gateId: user.id },\n          update: { email: user.email, name: user.name, lastName: user.lastName },\n          create: {\n            gateId: user.id,\n            email: user.email,\n            name: user.name,\n            lastName: user.lastName,\n          },\n        }),\n      ),\n    );\n  });\n}\n```\n\nEach app owns its roles and permissions. The SDK only fetches assigned Gate users so your app can manage local access data.\n\n\n### Confirming critical actions with OTP\n\nApps can request a short-lived step-up proof before running sensitive mutations. Add the `step_up` scope to the login flow, collect the user's OTP in your UI, then verify it server-side before executing the mutation.\n\n```ts\nimport { createStepUpHelpers } from \"@am25/gate-next\";\n\nconst stepUp = createStepUpHelpers({\n  issuer: process.env.GATE_ISSUER!,\n  clientId: process.env.GATE_CLIENT_ID!,\n});\n\nexport async function confirmDeleteProject(input: {\n  projectId: string;\n  code: string;\n}) {\n  const { proofToken } = await stepUp.verifyOtp({\n    action: \"project.delete\",\n    context: { projectId: input.projectId },\n    code: input.code,\n  });\n\n  await stepUp.requireProof(proofToken, {\n    action: \"project.delete\",\n    context: { projectId: input.projectId },\n  });\n\n  // Run the critical mutation here.\n}\n```\n\nFor non-idempotent actions, include a unique `intentId` in `context` and validate the same context when requiring the proof. Each app owns the final UI, commonly an `AlertDialog` with an OTP input.\n\n### In Server Actions\n\n```ts\n\"use server\";\n\nimport { getUser } from \"@/lib/auth\";\n\ninterface CreatePostData {\n  title: string;\n  content: string;\n}\n\nexport async function createPost(data: CreatePostData) {\n  const user = await getUser();\n  if (!user) throw new Error(\"Not authenticated\");\n\n  await prisma.post.create({\n    data: {\n      ...data,\n      authorId: user.id,\n    },\n  });\n}\n```\n\n<details>\n<summary>JavaScript version</summary>\n\n```js\n\"use server\";\n\nimport { getUser } from \"@/lib/auth\";\n\nexport async function createPost(data) {\n  const user = await getUser();\n  if (!user) throw new Error(\"Not authenticated\");\n\n  await prisma.post.create({\n    data: {\n      ...data,\n      authorId: user.id,\n    },\n  });\n}\n```\n\n</details>\n\n### Login button (Client Component)\n\n```tsx\n\"use client\";\n\nimport { getLoginUrl } from \"@am25/gate-next\";\n\nexport function LoginButton() {\n  const handleLogin = () => {\n    const url = getLoginUrl({\n      returnTo: \"/dashboard\",\n    });\n    window.location.href = url;\n  };\n\n  return <button onClick={handleLogin}>Log in</button>;\n}\n```\n\n<details>\n<summary>JavaScript version</summary>\n\n```jsx\n\"use client\";\n\nimport { getLoginUrl } from \"@am25/gate-next\";\n\nexport function LoginButton() {\n  const handleLogin = () => {\n    const url = getLoginUrl({\n      returnTo: \"/dashboard\",\n    });\n    window.location.href = url;\n  };\n\n  return <button onClick={handleLogin}>Log in</button>;\n}\n```\n\n</details>\n\n### Logout link\n\n```jsx\nexport function LogoutButton() {\n  return <a href=\"/api/auth/logout\">Log out</a>;\n}\n```\n\n## Scopes\n\nGate supports the following OIDC scopes:\n\n| Scope     | Claims included in the token          |\n| --------- | ------------------------------------- |\n| `openid`  | `sub` (required for OIDC)             |\n| `profile` | `name`, `lastName`, `picture`        |\n| `email`   | `email`                               |\n| `users`   | Allows fetching assigned users        |\n| `step_up` | Allows OTP confirmation for critical actions |\n\nThe default scope is `openid profile email users`. Add `step_up` when the app needs OTP confirmation for critical actions.\n\n## User data\n\nThe object returned by `getUser()` implements the `GateUser` interface:\n\n```ts\ninterface GateUser {\n  id: string;        // JWT sub\n  email: string;     // requires \"email\" scope\n  name: string;      // requires \"profile\" scope\n  lastName: string;  // requires \"profile\" scope\n  picture: string | null; // requires \"profile\" scope\n  isAdmin: boolean;\n}\n```\n\n### Difference between getSession and getUser\n\n| Function       | Returns              | User ID       | Recommended use   |\n| -------------- | -------------------- | ------------- | ----------------- |\n| `getSession()` | `JWTPayload \\| null` | `session.sub` | Access raw claims |\n| `getUser()`    | `GateUser \\| null`   | `user.id`     | Business logic    |\n\nUse `getUser()` for business logic. Use `getSession()` only if you need direct access to JWT claims.\n\n## API Reference\n\n### `createGateProxy(options)`\n\nCreates a proxy to protect routes in Next.js 16.\n\n| Option           | Type     | Required | Default                                   | Description                         |\n| ---------------- | -------- | -------- | ----------------------------------------- | ----------------------------------- |\n| `issuer`         | string   | Yes      |                                           | Gate server URL                     |\n| `clientId`       | string   | Yes      |                                           | App Client ID                       |\n| `redirectUri`    | string   | Yes      |                                           | Callback URI                        |\n| `protectedPaths` | string[] | No       | `[\"/dashboard\"]`                          | Routes to protect                   |\n| `publicPaths`    | string[] | No       | `[]`                                      | Public routes inside protectedPaths |\n| `cookieName`     | string   | No       | `\"am25_sess\"`                             | Cookie name                         |\n| `scopes`         | string[] | No       | `[\"openid\", \"profile\", \"email\", \"users\"]` | Scopes requested during redirect    |\n\nReturns `null` if the route does not require protection or the session is valid. Returns `NextResponse.redirect` if authentication is required.\n\n### `createLoginHandler(options)`\n\nCreates the local login endpoint. It generates a cryptographically random `state`, PKCE verifier/challenge, and OIDC nonce, then stores the transaction in a 10-minute httpOnly, SameSite=Lax, host-only cookie. In production the cookie uses the `__Host-` prefix.\n\n| Option            | Type     | Required | Default                                   | Description                         |\n| ----------------- | -------- | -------- | ----------------------------------------- | ----------------------------------- |\n| `issuer`          | string   | Yes      |                                           | Gate server URL                     |\n| `clientId`        | string   | Yes      |                                           | Client ID                           |\n| `redirectUri`     | string   | Yes      |                                           | Registered callback URI             |\n| `scopes`          | string[] | No       | `[\"openid\", \"profile\", \"email\", \"users\"]` | Scopes requested                    |\n| `defaultRedirect` | string   | No       | `\"/dashboard\"`                          | Local fallback after authentication |\n\n### `createCallbackHandler(options)`\n\nCreates the handler to exchange the authorization code for tokens.\n\n| Option            | Type   | Required | Default         | Description                           |\n| ----------------- | ------ | -------- | --------------- | ------------------------------------- |\n| `issuer`          | string | Yes      |                 | Gate server URL                       |\n| `clientId`        | string | Yes      |                 | Client ID                             |\n| `clientSecret`    | string | Yes      |                 | Client Secret                         |\n| `redirectUri`     | string | Yes      |                 | Callback URI (must match Gate config) |\n| `cookieName`      | string | No       | `\"am25_sess\"`   | Session cookie name                   |\n| `accessCookieName` | string | No       | `\"am25_at\"`     | Access token cookie name              |\n| `cookieDomain`    | string | No       |                 | Cookie domain (e.g. `.example.com`)   |\n| `cookieMaxAge`    | number | No       | `2592000` (30d) | Duration in seconds                   |\n| `defaultRedirect` | string | No       | `\"/dashboard\"`  | Route after login                     |\n\nThe handler rejects callbacks without the matching browser transaction, sends the PKCE verifier during the code exchange, validates the ID token audience and nonce, consumes the transaction cookie, and accepts only same-origin local return paths. It then stores `session_token` and `access_token` in separate httpOnly cookies; the access token cookie has a maximum age of 1 hour for server-side SDK helpers.\n\n### `createLogoutHandler(options)`\n\nCreates the logout handler.\n\n| Option         | Type   | Required | Default       | Description                                 |\n| -------------- | ------ | -------- | ------------- | ------------------------------------------- |\n| `redirectUri`  | string | Yes      |               | Callback URI (used to determine app origin) |\n| `issuer`       | string | Yes      |               | Gate URL                                    |\n| `clientId`     | string | Yes      |               | Client ID used to revoke the current grant  |\n| `clientSecret` | string | No       |               | Client secret for confidential clients      |\n| `cookieName`   | string | No       | `\"am25_sess\"` | Cookie name                                 |\n| `accessCookieName` | string | No   | `\"am25_at\"`   | Access token cookie name                    |\n| `cookieDomain` | string | No       |               | Cookie domain                               |\n| `redirectTo`   | string | No       | `\"/\"`         | Route after logout                          |\n\n**Federated logout:** Logout revokes the current OAuth grant before deleting either cookie and redirecting to Gate. If revocation cannot be confirmed, the handler returns `502` and preserves the cookies so the operation can be retried.\n\n### `verifyActiveAccessToken(token, options)`\n\nValidates an access token cryptographically and then calls Gate `/oauth/userinfo` to enforce current grant revocation, account state, client access, and live authorization claims.\n\n```ts\nimport { verifyActiveAccessToken } from \"@am25/gate-next\";\n\nconst claims = await verifyActiveAccessToken(token, {\n  issuer: process.env.GATE_ISSUER!,\n  clientId: process.env.GATE_CLIENT_ID!,\n});\n```\n\nUse this helper in resource-server endpoints that accept bearer tokens. `verifyTokenWithJWKS()` remains appropriate for purely cryptographic verification when live revocation is not required.\n\n### `createSessionHelpers(options)`\n\nCreates helpers to access the session in Server Components.\n\n| Option       | Type   | Required | Default       | Description                          |\n| ------------ | ------ | -------- | ------------- | ------------------------------------ |\n| `issuer`     | string | Yes      |               | Gate server URL                      |\n| `clientId`   | string | Yes      |               | Client whose grant must remain valid |\n| `cookieName` | string | No       | `\"am25_sess\"` | Cookie name                          |\n\nReturns a `SessionHelpers` object:\n\n| Helper                 | Returns                | Description                              |\n| ---------------------- | ---------------------- | ---------------------------------------- |\n| `getSession()`         | `JWTPayload \\| null`   | Raw JWT payload                          |\n| `getUser()`            | `GateUser \\| null`     | Formatted user data                      |\n| `isAuthenticated()`    | `boolean`              | Whether a session exists                 |\n| `requireAuth()`        | `GateUser`             | User data, throws if not authenticated   |\n| `requireAdmin()`       | `GateUser`             | User data, throws if not admin           |\n\nAll functions are cached per request using `React.cache()`. Session reads validate the JWT locally and confirm its current grant, user state, and client access with Gate. Validation fails closed when Gate cannot be reached.\n\n### `getLoginUrl(options)`\n\nGenerates the local URL that starts the OAuth flow through `createLoginHandler`.\n\n| Option          | Type   | Required | Default             | Description                    |\n| --------------- | ------ | -------- | ------------------- | ------------------------------ |\n| `loginEndpoint` | string | No       | `\"/api/auth/login\"` | Local login handler route      |\n| `returnTo`      | string | No       |                     | Local route after login        |\n\n### `getLogoutUrl(options)`\n\nGenerates the URL for the local logout endpoint.\n\n| Option           | Type   | Required | Default              | Description          |\n| ---------------- | ------ | -------- | -------------------- | -------------------- |\n| `logoutEndpoint` | string | No       | `\"/api/auth/logout\"` | Logout handler route |\n| `returnTo`       | string | No       |                      | URL after logout     |\n\n### `createAuthConfig(config)`\n\nCreates a reusable configuration that encapsulates `getLoginUrl` and `getLogoutUrl`.\n\n```ts\nimport { createAuthConfig } from \"@am25/gate-next\";\n\nconst auth = createAuthConfig({\n  loginEndpoint: \"/api/auth/login\",\n  logoutEndpoint: \"/api/auth/logout\",\n});\n\nconst loginUrl = auth.getLoginUrl(\"/dashboard\");\nconst logoutUrl = auth.getLogoutUrl(\"/\");\n```\n\n### `createUserHelpers(options)`\n\nCreates server-side helpers to fetch users assigned to the current Gate client and sync them into the app.\n\n| Option             | Type   | Required | Default     | Description              |\n| ------------------ | ------ | -------- | ----------- | ------------------------ |\n| `issuer`           | string | Yes      |             | Gate server URL          |\n| `accessCookieName` | string | No       | `\"am25_at\"` | Access token cookie name |\n\n| Helper        | Returns                 | Description                         |\n| ------------- | ----------------------- | ----------------------------------- |\n| `getUsers()`  | `Promise<GateAssignedUser[]>` | Fetches users from `/oauth/users` |\n| `syncUsers()` | `Promise<GateAssignedUser[]>` | Fetches users and calls your sync |\n\n### `createStepUpHelpers(options)`\n\nCreates server-side helpers for Gate OTP step-up challenges and proof validation.\n\n| Option             | Type   | Required | Default     | Description              |\n| ------------------ | ------ | -------- | ----------- | ------------------------ |\n| `issuer`           | string | Yes      |             | Gate server URL          |\n| `clientId`         | string | Yes      |             | App Client ID            |\n| `cookieName`       | string | No       | `\"am25_sess\"` | Session token cookie name         |\n| `accessCookieName` | string | No       | `\"am25_at\"`   | Access token fallback cookie name |\n\n| Helper              | Returns                              | Description                                |\n| ------------------- | ------------------------------------ | ------------------------------------------ |\n| `createChallenge()` | `Promise<StepUpChallenge>`           | Creates a Gate challenge for an action     |\n| `verifyChallenge()` | `Promise<StepUpProof>`               | Verifies a pre-created challenge           |\n| `verifyOtp()`       | `Promise<StepUpProof>`               | Creates a fresh challenge and verifies OTP |\n| `verifyProof()`     | `Promise<StepUpProofPayload \\| null>` | Validates a proof token with JWKS          |\n| `requireProof()`    | `Promise<StepUpProofPayload>`        | Validates a proof token or throws          |\n\nThe app must request the `step_up` scope during login before using these helpers.\n\n### `verifyTokenWithJWKS(token, issuer, expectedTyp)`\n\nVerifies a JWT using Gate’s public key (JWKS). Used internally by the SDK but available for manual verification.\n\n| Parameter     | Type   | Required | Description                                        |\n| ------------- | ------ | -------- | -------------------------------------------------- |\n| `token`       | string | Yes      | JWT to verify                                      |\n| `issuer`      | string | Yes      | Gate server URL                                    |\n| `expectedTyp` | string | No       | Expected header type (e.g. `\"st+jwt\"`, `\"at+jwt\"`) |\n\n### `clearJWKSCache(issuer)`\n\nClears the JWKS public key cache. Useful if Gate rotates its keys.\n\n| Parameter | Type   | Required | Description                              |\n| --------- | ------ | -------- | ---------------------------------------- |\n| `issuer`  | string | No       | Issuer URL. If omitted, clears all cache |\n\n## Exported types\n\nAll option interfaces and return types are exported for use in your own code:\n\n```ts\nimport type {\n  GateUser,\n  SessionHelpers,\n  SessionHelpersOptions,\n  GateProxyOptions,\n  LoginHandlerOptions,\n  CallbackHandlerOptions,\n  LogoutHandlerOptions,\n  LoginUrlOptions,\n  LogoutUrlOptions,\n  AuthConfig,\n  AuthConfigOptions,\n} from \"@am25/gate-next\";\n```\n\n## Authentication flow\n\n```\nUser            App (login/proxy)      Gate (IdP)           App (callback)\n  |                  |                      |                      |\n  | GET /dashboard   |                      |                      |\n  | ---------------> |                      |                      |\n  |                  |                      |                      |\n  |                  | Create state, PKCE, nonce                    |\n  |                  | Set transaction cookie                      |\n  |                  | Redirect to Gate     |                      |\n  | <--------------- |                      |                      |\n  |                  |                      |                      |\n  | Login on Gate                           |                      |\n  | --------------------------------------->|                      |\n  |                  |                      |                      |\n  | Redirect with authorization code       |                      |\n  | <---------------------------------------|                      |\n  |                  |                      |                      |\n  | GET /api/auth/callback?code=xxx&state=xxx                     |\n  | -------------------------------------------------------------->|\n  |                  |                      |                      |\n  |                  |                      | POST /oauth/token    |\n  |                  |                      | + code_verifier      |\n  |                  |                      |<---------------------|\n  |                  |                      |                      |\n  |                  |                      | Returns tokens       |\n  |                  |                      |--------------------->|\n  |                  |                      |                      |\n  | Validate state + nonce; consume transaction cookie             |\n  | Set-Cookie: am25_sess (httpOnly, RS256)                       |\n  | <--------------------------------------------------------------|\n  |                  |                      |                      |\n  | Redirect to /dashboard                                         |\n  | ---------------> |                      |                      |\n  |                  |                      |                      |\n  |                  | Verify token (JWKS) |                      |\n  |                  | -------------------> |                      |\n  |                  |                      |                      |\n  |                  | Public key (cache)  |                      |\n  |                  | <------------------- |                      |\n  |                  |                      |                      |\n  | Page OK          |                      |                      |\n  | <--------------- |                      |                      |\n```\n\n## Token verification (RS256)\n\nThe SDK verifies tokens using Gate’s public key obtained from the JWKS endpoint:\n\n```\nGET {issuer}/.well-known/jwks.json\n```\n\n- Only Gate has the private key (used to sign tokens)\n- Apps only need the public key (used to verify tokens)\n- The public key is automatically cached in memory\n\n## Domain cookies\n\nApps share sessions by domain:\n\n- Apps on `*.example.com` → cookie on `.example.com`\n- Apps on `*.example.com` → cookie on `.example.com`\n\nEach domain has its own session. They do not cross.\n\n## Access control\n\nGate manages access at two levels:\n\n**Per application:** In the Gate dashboard you configure which users can access each app. Administrators automatically have access to all apps. If an unauthorized user tries to authenticate, Gate returns a 403 error.\n\n**Per app roles and permissions:** Each client app owns its own role and permission model. Gate only authenticates users and controls which users can access each app.\n\n## Internal vs third-party clients\n\nGate distinguishes two types of OAuth clients:\n\n| Type                       | Consent             | Use case                            |\n| -------------------------- | ------------------- | ----------------------------------- |\n| **Internal (first-party)** | No, auto-approved   | Apps within the AM25 ecosystem      |\n| **Third-party**            | Yes, consent screen | External apps integrating with Gate |\n\nConfigured in the Gate dashboard when creating or editing a client.\n\n## Compatibility with standard libraries\n\nGate is an OAuth 2.0 and OpenID Connect compatible Identity Provider. Besides this SDK, you can integrate it with any library that supports OIDC Discovery:\n\n```\nDiscovery: {issuer}/.well-known/openid-configuration\nJWKS:      {issuer}/.well-known/jwks.json\n```\n","readmeFilename":"README.md"}